[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[cobalt-users] SMTP server down, NOT ANY MORE!!!!
- Subject: [cobalt-users] SMTP server down, NOT ANY MORE!!!!
- From: jale@xxxxxxxxxx
- Date: Thu Aug 29 17:45:00 2002
- List-id: Mailing list for users to share thoughts on Sun Cobalt products. <cobalt-users.list.cobalt.com>
In case anyone is interested, I believe my SMTP down issue is resolved. It
was the RAQ, it was our host-site-company. I received the email below from
them late this afternoon, and since they changed their side we have been
FANTASTIC. What they changed has fixed so many things, such as:
1) my email was logging on very slowly, send and receive, now it is
instantaneous
2) ftp logon was very slow, even from an NT box sitting right next to the
RAQ, like 5 seconds just to logon, another 3 to get the directory listing,
now it is instantaneous
I have not lost SMTP for about 5 hours now, I had been losing it every
30-60 minutes.
The list of what is working better goes on. Here's what was found
Danny,
I think I found the problem. It looks like your RAQ server is acting as
it's own DNS server. The access-list on our router didn't allow your
server to do DNS lookups to other DNS servers on the Internet. We were
assuming you were using our DNS servers of 216.182.xxx.xxx and
216.182.xxx.yyy I've opened up your access list slightly to allow UDP
traffic from port 53 on any server on the Internet to reach your server on
ports higher than 1023. This is the default behavior of many DNS servers,
to use high UDP ports for receiving answers to DNS queries. Once I added
that line, all your services sped up a lot. I think this fixed the
problem. Let me know. Below is your current access list:
....
If you want to make it a little more secure, you can set Bind to use a
query source port of 53 (which I'll have to reconfigure the access list
again to allow) so all the answers to DNS queries return on port 53. If
you want it even more secure, setup your DNS server to use forwarders and
point it at our DNS servers. I'll then be able to block the traffic above
1023 (originating from port 53) to your RAQ server since you'll be asking
our DNS servers to resolve everything.
Hope this can help someone else out there, at least it will be in the
archives now.
Thanks for all the assistance, a special thanks to Joe at hardynet who
generously offered to lend personal assistance.
Great group you are!!!
Jale, Danny is real life.